AcademySoftwareFoundation / AcademySoftwareFoundation/OpenColorIO
Modify PyPI wheel generation to use Trusted Publisher
オープン
Build Issue
Feature Request
- 主要言語
- C++
- スター
- 2.1k
- フォーク
- 505
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
PyPI's preferred way to upload wheels is their Trusted Publisher method. From their website: "PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
We should update OCIO to use this method.
コントリビューションガイド
調査の方向性
まず、OCIO の現在の PyPI wheel 生成および upload ワークフローを特定し、次に issue にリンクされている PyPI Trusted Publisher ガイダンスを読む。完了条件は、長期間有効なパスワードや API token を必要とせず、ワークフローが Trusted Publisher を通じて wheel を公開すること。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- python
- 領域
- release
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100